IBM Support

Is my Guardium collector capturing application server traffic from EBS?

Question & Answer


Question

How can I check that Oracle E-Business Suite (EBS) traffic is being captured by the appliance?

Answer

There are a few EBS tables listed below that you will see in Guardium reports if you are capturing EBS traffic successfully.

  • FND_USER
  • ICS_SESSION
  • FND_RESPONSIBILITY

You can check for these tables by applying a condition to the SQL column in interactive GUI reports, or searching in a pdf report.

If you do not see any mention of these tables in your report it is very likely you are not capturing any traffic from EBS.

In that case you should double check your Inspection Engine setting with your Database Administrator to ensure you should be collecting traffic from the application server.

Check in the GUI->Administration Console->Local Taps->S-TAP Control. Under the Inspection Engines tab for the S-TAP in question.

Another possibility is that Policy rule(s) are filtering the EBS traffic by mistake somehow.

If the Policy and Inspection Engine settings are confirmed to be correct you should open a PMR to IBM support. Attach to the PMR:

  • support must_gather sniffer_issues - Details here
  • slon trace while you generate some traffic on the application server - Details here
  • guard_diag script from the application server - Details here

Further Information

Guardium Administration Help Book - Inspection Engine Configuration

[{"Product":{"code":"SSMPHH","label":"IBM Security Guardium"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Component":"Guardium Database Activity Monitor","Platform":[{"code":"PF002","label":"AIX"},{"code":"PF010","label":"HP-UX"},{"code":"PF016","label":"Linux"},{"code":"PF027","label":"Solaris"},{"code":"PF033","label":"Windows"},{"code":"PF035","label":"z\/OS"}],"Version":"9.0;8.2;8.1;8.0.1;8.0","Edition":"All Editions","Line of Business":{"code":"LOB24","label":"Security Software"}}]

Document Information

Modified date:
16 June 2018

UID

swg21664216